ZeroHour

inc ransom

ransomware group · aka Inc Ransom, IncRansom · unknown (no authoritative public attribution; no confirmed country of operation) · active since 2023-07

Victims · 7d
3▼6
Victims · 30d
36active targets
Victims · 90d
106
All-time (tracked)
917since 2023-08-09
Last post
09-10 17:41UTC
Estimated earnings
public reporting
Profile · glm-5.3-flash · updated

Inc Ransom is a ransomware and data-extortion group first observed in July 2023, known for double extortion using a Tor-hosted leak site. Vendor research links its initial access to exploitation of internet-facing Citrix NetScaler appliances (CVE-2023-3519, CVE-2023-4966). It drew broad attention in March 2024 for the NHS Dumfries and Galloway breach in Scotland and in 2024 for a claimed theft of data from Citrix. Researchers have documented Windows and Linux/ESXi encryptor variants for the group's tooling. Its organizational structure (single crew versus affiliates) and aggregate earnings are not publicly established, and it remains active with intermittent victim postings.

Tactics & tooling
  • Initial access via exploitation of unpatched internet-facing Citrix NetScaler ADC/GateWay appliances (CVE-2023-3519; CVE-2023-4966), per vendor reporting
  • Data exfiltration before encryption, followed by double extortion on a Tor leak site
  • Separate encryptor builds for Windows and for Linux/ESXi environments documented by researchers
  • Ransom notes dropped on compromised systems; negotiation via leak-site chat, email, or Tox
  • Targets organizations holding sensitive records; healthcare and public-sector victims emphasized in public coverage
  • Emphasis on large data volumes in extortion messaging, including claimed terabyte-scale thefts in 2024 reporting
  • Organizational model unclear; affiliate involvement not confirmed, so per-incident attribution should be treated cautiously
Targeted sectors
HealthcareGovernment/Public SectorTechnologyManufacturing
Notable public victims

NHS Dumfries and Galloway (Scotland) — March 2024, widely reported; group published stolen data, Citrix — June 2024 claimed breach; the group alleged roughly 1 TB of stolen data, per BleepingComputer (2024), Yamaha Motor Philippines subsidiary — 2023 listing reported in security press, Mediengruppe Thiel (mediengruppethiel.de) — listed on the group leak site, September 2026, per this dashboard, Wellness Partners network — listed on the group leak site, September 2026, per this dashboard

CVEs linked to their intrusions
Estimated earnings

No public figure.

Leak-site victims

VictimDiscoveredDetails
jms building corporation · 5d ago
cullottalaw.com · 5d ago
https://mediengruppethiel.de/ · 6d ago
Wellness Partners network(combined revenue) · 8d ago
myglobal.com · 12d ago
Asfaltos y Pavimentos S.A. (Asfalpasa) · 13d ago
Westfield Public School District · 13d ago
Trucka · 13d ago
Policlinico Triestino · 13d ago
Multiver Ltée · 13d ago
Metales Panamericanos · 13d ago
specialtytextile.com · 13d ago
FFKR Architects · 15d ago
New Century Ophthalmology Group · 15d ago
zummocorp.com · 15d ago
www.lichtvision.com · 15d ago
www.renorefractories.com · 15d ago
cimbsecurities.com · 15d ago
wittmann · 17d ago
Oilquip Inc · 17d ago
BENCIVIL · 19d ago
Rohloff Group · 19d ago
Ruby Seven Studios · 19d ago
el-group · 23d ago
BANGKOKCABLE · 27d ago
UNIPLASTICS.COM · 27d ago
CDGARVINLAW · 27d ago
EXEL · 27d ago
SD Associates Sdn Bhd · 28d ago
Third Coast Bancshares · 28d ago
Foresee Pharmaceuticals · 28d ago
SpearFin Ltd · 28d ago
ssf-int.com ssf-ing.de · 28d ago
nyklawfirm.com nyk.ae · 28d ago
Lansing Urgent Care · 29d ago
Otter Tail County, Minnesota · 29d ago
cambrialawfirm.com · Aug 14, 2026
https://pacific-construction.com/ · Aug 14, 2026
clgroup · Aug 13, 2026
gamaus.com · Aug 12, 2026
stuartandassociates.com · Aug 12, 2026
BEDC.COM.AU · Aug 12, 2026
diabetesandmetabolism.com · Aug 12, 2026
Louisville Bar Association · Aug 8, 2026
ATMS · Aug 7, 2026
vprj.org · Aug 6, 2026
lantisnet.com · Aug 5, 2026
Loyalist College · Aug 5, 2026
TRULITE GLASS & ALUMINUM SOLUTIONS · Aug 5, 2026
clintonhealthaccess.org · Aug 4, 2026

In the newsAll →

No articles mention this group yet.

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .